BlueMoon exploit kit chaining Chrome and Windows zero-days spreads to 4 espionage groups
TechNadu · x · 2026-09-10
Per Proofpoint, the new BlueMoon Chrome-to-Windows exploit kit spread to 4 espionage-linked threat groups within days. It chains a Chromium V8 type-confusion flaw, a V8 sandbox escape, and a Windows kernel LPE zero-day. TA412/APT31 was the first observed user.
More from Safety
- OpenAI commits $5M to study how generative AI affects teens — JeremyNguyenPhD · 2026-09-10
- Guardian op-ed: We've started losing control of AI — it's time to pause the race — nordicinst · 2026-09-10
- OpenAI chief scientist Jakub Pachocki warns of 'alien intellect exceeding our own' — TVP_World_News · 2026-09-10
- Labs reportedly turn proprietary chain-of-thought into synthetic training data; TOS only covers user-visible IO — erikphoel · 2026-09-10
- Commenter: anyone regulating AI should prove they understand how it works — intellectronica · 2026-09-10
- UK MP Al Carns: AI has a 10% chance of wiping out humanity, unchecked rollout 'irresponsible' — connoraxiotes · 2026-09-10